A third of the people who use AI chatbots have told one a secret they would not tell someone they trust. The figure comes from a DuckDuckGo survey reported by CNET, and it sits beside a number from the Washington Post: chatbot conversations have surfaced in public records in at least 12 court cases over the past two years. The same survey found that 53% of regular users did not know chatbots can train on what they type, and 75% did not know those conversations can be demanded through a court.
Part of the reason is the metaphor people reach for. A conversation with a model can feel like talking to a mirror, or like typing into a document nobody else opens. The systems are built closer to a one-way mirror: the user sees the interface and has no view of who may be standing behind it.
The list of who might be is longer than most users assume. Technology companies hold the logs. Police departments and lawyers can ask for them. So can an employer, when the employee is working inside a corporate AI service. How long OpenAI, Anthropic and the rest keep the contents of those conversations is not publicly established, and the Washington Post describes several situations in which the law can require them to preserve chat logs rather than delete them.
Then there is the failure that requires no legal process at all. In July a large collection of conversations with Anthropic's Claude turned up on the open internet. It was not the first time.
Jen King, a privacy researcher at the Stanford Institute for Human-Centered Artificial Intelligence, told the Washington Post that full confidentiality cannot be guaranteed. What it would take, she said, is a service with a temporary or effectively anonymous conversation mode plus a browser that does not track the user. If either condition fails, the conversation can be stored and reachable by other parties.
Stack those two conditions and count who actually meets them. Ephemeral or anonymous mode, running on a non-tracking browser, is not a setting most people have; it is a configuration most people will never assemble. Describing confidentiality as something a user achieves by combining the right product with the right browser puts the burden in the one place it cannot be carried, and the survey shows where it lands instead.
The gap between 53% and 75% is the part worth looking at. Training is the exposure people have been taught to worry about, and it is the milder one — it leaves a statistical residue inside a model. Discovery produces a transcript with a name on it, read out in a proceeding. Three quarters of regular users have no idea the second thing is possible, and it has already happened in at least a dozen cases.
None of this reads as a failure of user education. A third of users telling a chatbot something they withhold from people close to them is not a misunderstanding to be fixed with a clearer privacy notice. It is the product working. The interface that makes disclosure easy is the same interface that turns disclosure into a durable, searchable, subpoenable record — and the one figure that would let a user weigh that trade, how long the logs live, is the figure nobody publishes.
The value of a confessional depends on people speaking freely. The value of a chat log depends on everything being written down. The industry is selling both at once, and only one of them appears at sign-up.